The customer list is often the most valuable thing a small business sells, and it is personal information about people who never agreed to be handed to a stranger. Section 7.2 of PIPEDA makes that transfer lawful without their consent — on conditions. The way most owner-operated deals actually run, a spreadsheet emailed to a buyer who has signed only an NDA, does not meet them.
Key takeaways
SECTION 01 OF 10
A customer database is personal information — section 2(1) defines that as “information about an identifiable individual” — and subsection 4(1) applies the Act to information handled “in the course of commercial activities”. Selling the business is one; so is the diligence before it.
The baseline is consent. Clause 4.3 of Schedule 1: “The knowledge and consent of the individual are required for the collection, use, or disclosure of personal information, except where inappropriate.” Nobody who signed a landscaping contract agreed to be disclosed to a competitor.
Section 7.2 solves that. Subsection (1), marginal note Prospective business transaction, lets parties to a prospective business transaction “use and disclose personal information without the knowledge or consent of the individual” — then says when. Added by the Digital Privacy Act, S.C. 2015, c. 32.
SECTION 02 OF 10
The definition in section 2(1) is wide. It includes the purchase or sale “of an organization or a part of an organization, or any of its assets”, a merger, “the making of a loan or provision of other financing”, taking “a security interest in… any assets or securities”, and “the lease or licensing of any of an organization’s assets”.
So a refinancing qualifies, and a lender running credit diligence on a receivables ledger sits in the same provision as a buyer. On a share purchase the company holding the data does not change, so nothing is disclosed at closing — the diligence disclosure still is. Treadstone Law makes the commercial point, that privacy obligations travel with the data, though it names no statute and does not reach section 7.2.
SECTION 03 OF 10
Paragraph 7.2(1)(a) requires an agreement binding the recipient to do three things: use and disclose the information “solely for purposes related to the transaction”; “protect that information by security safeguards appropriate to the sensitivity of the information”; and, if the deal fails, return or destroy it.
Paragraph (b) adds necessity in two limbs: the information must be necessary “to determine whether to proceed with the transaction” and, if the decision is to proceed, “to complete it”. Necessity is measured against the decision being made, not the buyer’s curiosity.
Read that against a real deal: a standard NDA promises confidentiality and says nothing about safeguards or destruction. Treadstone Law’s guide to confidentiality in a sale is candid about the gap — it covers staged disclosure and breach consequences, and does not address non-use, destruction, or personal information at all.
SECTION 04 OF 10
Nothing here entitles a buyer to the raw database on day one. Most of diligence is answered by counts, cohorts, revenue concentration and churn — none of which needs a name. A buyer has to know the top five accounts are 40% of revenue, not who they are.
Treadstone Law advises withholding the identifiable list until a buyer “has shown real seriousness”, and its data room guide gives the mechanics: role-based access, view-only documents, watermarking, a log of who opened what and when. Sensitivity sets how much the safeguards term must deliver — clause 4.3.4 warns that “any information can be sensitive, depending on the context”.
SECTION 05 OF 10
Subparagraph 7.2(1)(a)(iii) is the term most often missing and most often needed: the recipient must, “if the transaction does not proceed”, “return that information to the organization that disclosed it, or destroy it, within a reasonable time”. Without it in the agreement, the disclosure was never authorised at all.
This is the scenario owners fear, and Treadstone Law’s answer is purely contractual — a non-use covenant, and the honest note that suing afterwards is “a remedy after the fact”. The statutory route is stronger: return-or-destroy is a precondition, not a bargaining point. And it has to be operationalised: closing a data room is not destruction, and says nothing about copies already exported to the buyer’s advisers. Get written confirmation of deletion from each.
SECTION 06 OF 10
Subsection (1) covers diligence only. Once the deal completes, subsection (2) — marginal note Completed business transaction — takes over with its own conditions. It permits use of information “which was disclosed under subsection (1)”, which ties the two: what was not validly disclosed before closing does not become valid after it.
The post-closing agreement must bind each party to use the information “solely for the purposes for which the personal information was collected… before the transaction was completed”. The buyer inherits the seller’s purposes and no more: a warranty-service list does not become a marketing list because it changed hands.
It must also require safeguards and “give effect to any withdrawal of consent made under clause 4.3.8”, and paragraph (b) requires the information to be “necessary for carrying on the business… that was the object of the transaction”. Treadstone Law states the underlying rule: “use information only for the stated purpose”.
SECTION 07 OF 10
Paragraph 7.2(2)(c) is the condition most consistently ignored in small deals. It requires that “one of the parties notifies the individual, within a reasonable time after the transaction is completed, that the transaction has been completed and that their personal information has been disclosed under subsection (1)”.
Note the structure. This is not a free-standing duty; it is one of three conditions on which subsection (2) operates. No notice, no exception — and post-closing use falls back to clause 4.3, which needs a consent nobody has. The notice must say two things: that the deal closed, and that the individual’s information moved. “Exciting news, we’ve been acquired” says only the first.
“One of the parties” means the deal can allocate it, and the purchase agreement should. Access rights survive throughout — a person can ask what a business holds about them, “how it’s being used, and who it has been disclosed to”.
SECTION 08 OF 10
The exception has a hole cut in it. Subsection 7.2(4), marginal note Exception, in full: “Subsections (1) and (2) do not apply to a business transaction of which the primary purpose or result is the purchase, sale or other acquisition or disposition, or lease, of personal information.”
Read “or result” carefully: stated intention is not the only test, so recitals cannot rescue a transaction whose effect is a transfer of personal information. The definition of commercial activity in section 2(1) already singles out the trade, reaching “the selling, bartering or leasing of donor, membership or other fundraising lists”.
A common small-deal structure runs aground here. Treadstone Law describes it — a buyer wanting only the brand and the relationships can buy the intellectual property alone — “the trademark, trade name, and goodwill, along with the customer list”. That page covers the corporate and GST/HST consequences and expressly does not address privacy law. Strip out the staff, equipment and contracts, and what remains may be a deal whose primary result is acquiring a database. Section 7.2 then does nothing, and the transfer needs consent.
SECTION 09 OF 10
Subsection 7.2(3) is one sentence: “An organization shall comply with the terms of any agreement into which it enters under paragraph (1)(a) or (2)(a).” The agreement is not merely the gateway to the exception — breaching it breaches the Act, putting it in front of the Privacy Commissioner and not only the counterparty.
Safeguards stay live: clause 4.7 requires protection “appropriate to the sensitivity of the information”, and a failure engages the breach regime — reporting is required, as Treadstone Law puts it, “when it is reasonable to believe the breach creates a real risk of significant harm”, plus a record of every breach. Its privacy diligence guide warns that “a data practice problem inherited from the seller doesn’t stay the seller’s problem once you’re the one holding the data”.
SECTION 10 OF 10
PIPEDA is federal and reaches commercial activity, but it is not Canada’s only private-sector regime. Paragraph 26(2)(b) lets the Governor in Council exempt organizations where provincial legislation “substantially similar to this Part” covers information handled “within that province”. The Privacy Commissioner identifies Alberta, British Columbia and Quebec as the three.
All three legislate the same problem, none identically. Section 20 of British Columbia’s PIPA requires post-transaction notice, and bars the exception for a deal “that does not involve substantial assets… other than this personal information”. Section 22 of Alberta’s PIPA requires the restricting agreement and return-or-destruction on a failed deal, but has no notification requirement at all. Section 18.4 of Quebec’s private-sector Act requires an agreement with four stipulated undertakings, and the acquiring party “must notify the person concerned that it now holds personal information concerning him”.
Location does not settle it. The Commissioner states that businesses handling information “that crosses provincial or national borders… are subject to PIPEDA, regardless of the province or territory in which they are based”. Treadstone Law is right that Ontario has no private-sector privacy statute of its own — the easy case. Where a deal crosses a provincial line, settle which regime governs before the first spreadsheet moves.
Sources